pirikara/Supply Chain Guard

Multi-ecosystem frozen install check + GitHub Advisory (malware) + OSSF malicious packages + GuardDog analysis

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
enable-ossfCheck against OpenSSF malicious-packages (warn)true
enable-guarddogRun GuardDog npm scan via Docker (heuristics: typo, suspicious install scripts, etc.)false
guarddog-failFail the job when GuardDog finds findings (>0)false
pr-commentComment security scan results summary on PRfalse
warn-onlyWarn (do not fail) for: minimumAge / OpenSSF / GuardDogtrue
workdirWorking directory (where package.json/lockfile live).
namedescription
changed-countCount of changed deps in this PR (from dep-diff)
malware-hits-countCount of GH Advisory (type: malware) hits (best-effort)
guarddog-findings-countCount of GuardDog findings (best-effort)